dc dotCreds
ISC2 CCSP Practice Test

CCSP Practice Test

Start today’s free 10-question CCSP set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 23, 2026, 8:12 PM CDT

Go Pro - One Time Unlock

Unlock the full CCSP bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 CCSP questions

Use this CCSP practice test to review ISC2 Certified Cloud Security Professional. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective 6.1 Articulate legal requirements and unique risks within the cloud environment 6. Legal, Risk and Compliance (13%)

A court order requires preservation and production of cloud-hosted records. Which capability is MOST important to support defensible eDiscovery?

Concept tested:
Question 2 of 10
Objective 4.4 Apply cloud software assurance and validation 4. Cloud Application Security (16%)

A development team is implementing interactive application security testing (IAST) to identify vulnerabilities in a new microservice-based e-commerce platform. To maximize the effectiveness of the IAST tool, which action is MOST critical to prioritize during implementation?

Concept tested:
Question 3 of 10
Objective 6.5 Understand outsourcing and cloud contract design 6. Legal, Risk and Compliance (13%)

A cloud customer is negotiating termination provisions. Which requirement is MOST important for protecting customer data at the end of the relationship?

Concept tested:
Question 4 of 10
Objective 2.7 Plan and implement data retention, deletion, and archiving policies 2. Cloud Data Security (20%)

A compliance rule requires transaction records to remain retrievable for seven years and then be disposed of unless a legal hold applies. Which policy BEST satisfies the requirement?

Concept tested:
Question 5 of 10
Objective 3.2 Design a secure data center 3. Cloud Platform and Infrastructure Security (17%)

A security architect is reviewing environmental resilience for a cloud data center. Which condition should trigger the MOST immediate design concern?

Concept tested:
Question 6 of 10
Objective 5.5 Manage communication with relevant parties 5. Cloud Security Operations (17%)

An organization’s cloud infrastructure has experienced a data breach. Considering the evolution of incident response, what is the most critical element for ensuring the success of the response efforts?

Concept tested:
Question 7 of 10
Objective 1.1 Understand cloud computing concepts 1. Cloud Concepts, Architecture and Design (17%)

An enterprise uses several cloud providers and wants an independent party to assess whether each provider's controls and operations meet stated criteria. Which cloud actor is MOST directly associated with this function?

Concept tested:
Question 8 of 10
Objective 4.7 Design appropriate Identity and Access Management (IAM) solutions 4. Cloud Application Security (16%)

A SaaS application accepts authentication assertions from the enterprise IdP and then grants access to its own service. In federation terminology, what role does the SaaS application perform?

Concept tested:
Question 9 of 10
Objective 6.3 Understand audit process, methodologies, and required adaptations for a cloud environment 6. Legal, Risk and Compliance (13%)

A gap analysis finds that a required control is not implemented by either the cloud customer or provider because each assumed the other was responsible. What is the MOST important corrective action?

Concept tested:
Question 10 of 10
Objective 2.9 Comprehend data protection of Artificial Intelligence (AI) and Machine Learning (ML) data 2. Cloud Data Security (20%)

A team is preparing a confidential training dataset for a managed ML service. Which control should be prioritized BEFORE training begins?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
CCSP Pro $4.99 one-time

50 Exam Practice Test $1.99 one-time

A 50-question CCSP PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

ISC2 Bundle $9.99 one-time

Unlock all 4 active ISC2 Bundle practice banks in one permanent purchase.

What’s includedISC2 CC, ISC2 SSCP, ISC2 CCSP, ISC2 CISSP
All Access $6.99/month

Unlock every active practice exam, bundle and path experience, Pro course and study content, and included downloads.

What’s includedEvery current and future active practice exam, All active bundle and career-path practice content, Pro course lessons, study content, and supported paid downloads

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full CCSP bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily CCSP practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily CCSP set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A court order requires preservation and production of cloud-hosted records. Which capability is MOST important to support defensible eDiscovery?

Answer choices

  1. A. Delete duplicates immediately without documenting the process, for the described technical objective and its associated operational control requirements, for consideration.
  2. B. Move all records to a new provider before collection, as the primary implementation for the described business requirement.
  3. C. Preserve relevant data and metadata under legal hold with traceable collection and chain-of-custody controls, as the primary proposed approach.
  4. D. Disable audit logging to reduce discoverable information, for the required operational result and control objective.

Correct answer

Preserve relevant data and metadata under legal hold with traceable collection and chain-of-custody controls, as the primary proposed approach.

eDiscovery requires the organization to identify, preserve, collect, and produce relevant information in a manner that maintains integrity, traceability, and legal-hold requirements.

Wrong-answer review

  • A. Delete duplicates immediately without documenting the process, for the described technical objective and its associated operational control requirements, for consideration.: Not the best answer. This option does not most directly satisfy the scenario or the cited guidance; preserve relevant data and metadata under legal hold with traceable collection and chain-of-custody controls is the better-supported action.
  • B. Move all records to a new provider before collection, as the primary implementation for the described business requirement.: Not the best answer. This option does not most directly satisfy the scenario or the cited guidance; preserve relevant data and metadata under legal hold with traceable collection and chain-of-custody controls is the better-supported action.
  • D. Disable audit logging to reduce discoverable information, for the required operational result and control objective.: Not the best answer. This option does not most directly satisfy the scenario or the cited guidance; preserve relevant data and metadata under legal hold with traceable collection and chain-of-custody controls is the better-supported action.

Extra learning features

Interview question

Q: Explain the importance of chain-of-custody controls in eDiscovery, detailing how they contribute to the integrity and admissibility of evidence. Strong answer: Chain-of-custody controls are critical for establishing the provenance of evidence, ensuring it hasn't been tampered with or compromised. Traceability through documented handling, secure storage, and authorized personnel provides a verifiable audit trail, bolstering the reliability of the data in legal proceedings.

  • traceability
  • audit trail
  • integrity
  • provenance
  • secure storage

Caution: Do not simply restate the question or ask for a product name.

Why this matters

Failure to properly preserve and track data during eDiscovery can lead to evidence being deemed inadmissible in court, resulting in significant legal setbacks and potentially impacting the outcome of a case. Maintaining a verifiable chain of custody is paramount to ensuring the integrity of the evidence and its acceptance by the judicial system.

Objective/domain: 6. Legal, Risk and Compliance (13%)

Source: Guide to Integrating Forensic Techniques into Incident Response (NIST SP 800-86)

Question 2 A development team is implementing interactive application security testing (IAST) to identify vulnerabilities in a new microservice-based e-commerce platform. To maximize the effectiveness of the IAST tool, which action is MOST critical to prioritize during implementation?

Answer choices

  1. A. Instrumenting the application to observe runtime behavior and measure control effectiveness, under the documented operational and governance requirements.
  2. B. Monitoring network traffic for suspicious outbound connections, for the affected environment.
  3. C. Implementing a web application firewall (WAF) to protect against common attacks, as the primary proposed approach.
  4. D. Performing static code analysis to identify vulnerabilities before deployment, for the stated scenario.

Correct answer

Instrumenting the application to observe runtime behavior and measure control effectiveness, under the documented operational and governance requirements.

Objective/domain: 4. Cloud Application Security (16%)

Source: Security and Privacy Controls (NIST SP 800-53 Rev. 5)

Question 3 A cloud customer is negotiating termination provisions. Which requirement is MOST important for protecting customer data at the end of the relationship?

Answer choices

  1. A. Remove customer access before any export occurs, for the stated implementation and support requirements.
  2. B. Leave deletion procedures unspecified, for the required operational result and control objective.
  3. C. Allow the provider to retain all customer data indefinitely, within the documented operational, security, ownership, and validation requirements.
  4. D. Define data return/export, retention, secure deletion, verification, and timing responsibilities, for the described technical objective.

Correct answer

Define data return/export, retention, secure deletion, verification, and timing responsibilities, for the described technical objective.

Objective/domain: 6. Legal, Risk and Compliance (13%)

Source: Cloud Computing Synopsis and Recommendations (NIST SP 800-146)

Question 4 A compliance rule requires transaction records to remain retrievable for seven years and then be disposed of unless a legal hold applies. Which policy BEST satisfies the requirement?

Answer choices

  1. A. Archive records for the defined retention period, suspend disposal when legally held, and securely delete them when retention obligations end, under the organization’s defined implementation and exception-management process.
  2. B. Rely on application users to decide when each record is deleted, for the described technical objective and its associated operational control requirements, for the described technical objective.
  3. C. Delete records after one year if storage costs increase, for the described technical objective and its associated operational control requirements.
  4. D. Keep every record indefinitely, for the described technical objective and its associated operational control requirements, under the documented operational and governance requirements.

Correct answer

Archive records for the defined retention period, suspend disposal when legally held, and securely delete them when retention obligations end, under the organization’s defined implementation and exception-management process.

Question 5 A security architect is reviewing environmental resilience for a cloud data center. Which condition should trigger the MOST immediate design concern?

Answer choices

  1. A. Servers have asset tags, for the described technical objective and its associated operational control requirements, for review.
  2. B. Critical cooling has no redundant capacity or alternate path, for this task.
  3. C. The site uses hot-aisle/cold-aisle containment, for the stated security, delivery, and accountability requirements.
  4. D. The racks use standardized rail kits, for the affected environment.

Correct answer

Critical cooling has no redundant capacity or alternate path, for this task.

Objective/domain: 3. Cloud Platform and Infrastructure Security (17%)

Source: Security and Privacy Controls for Information Systems and Organizations (NIST SP 800-53 Rev. 5)

Question 6 An organization’s cloud infrastructure has experienced a data breach. Considering the evolution of incident response, what is the most critical element for ensuring the success of the response efforts?

Answer choices

  1. A. Detailed forensic analysis of the compromised systems to identify the specific vulnerabilities exploited, within the proposed design.
  2. B. Active participation of numerous internal and external parties with diverse roles and responsibilities across various locations, within the proposed design.
  3. C. Strict adherence to a predefined incident response plan developed solely by internal incident handlers, within the stated policy framework.
  4. D. Immediate isolation of all affected systems and a complete shutdown of the cloud environment, under the organization’s defined implementation and exception-management process.

Correct answer

Active participation of numerous internal and external parties with diverse roles and responsibilities across various locations, within the proposed design.

Objective/domain: 5. Cloud Security Operations (17%)

Source: Incident Response Recommendations (NIST SP 800-61 Rev. 3)

Question 7 An enterprise uses several cloud providers and wants an independent party to assess whether each provider's controls and operations meet stated criteria. Which cloud actor is MOST directly associated with this function?

Answer choices

  1. A. Cloud auditor, as presented.
  2. B. Cloud carrier, within the stated policy framework.
  3. C. Cloud consumer, for the required outcome.
  4. D. Cloud service broker, as described.

Correct answer

Cloud auditor, as presented.

Objective/domain: 1. Cloud Concepts, Architecture and Design (17%)

Source: NIST Cloud Computing Reference Architecture (NIST SP 500-292)

Question 8 A SaaS application accepts authentication assertions from the enterprise IdP and then grants access to its own service. In federation terminology, what role does the SaaS application perform?

Answer choices

  1. A. Credential issuer only, as presented.
  2. B. Relying party, for evaluation.
  3. C. Identity provider, under the documented operational and governance requirements.
  4. D. Cloud carrier, for the required business outcome.

Correct answer

Relying party, for evaluation.

Objective/domain: 4. Cloud Application Security (16%)

Source: Digital Identity Guidelines: Federation and Assertions (NIST SP 800-63C-4)

Question 9 A gap analysis finds that a required control is not implemented by either the cloud customer or provider because each assumed the other was responsible. What is the MOST important corrective action?

Answer choices

  1. A. Clarify the shared-responsibility assignment and implement ownership for the control, under the stated decision criteria.
  2. B. Change providers without investigating responsibility, for the described technical objective and its associated operational control requirements.
  3. C. Treat the gap as accepted automatically, for the specified implementation requirement.
  4. D. Remove the control from the baseline, for the required operational result and control objective.

Correct answer

Clarify the shared-responsibility assignment and implement ownership for the control, under the stated decision criteria.

Objective/domain: 6. Legal, Risk and Compliance (13%)

Source: Guidelines on Security and Privacy in Public Cloud Computing (NIST SP 800-144)

Question 10 A team is preparing a confidential training dataset for a managed ML service. Which control should be prioritized BEFORE training begins?

Answer choices

  1. A. Publish the dataset to improve reproducibility, as the primary implementation for the described business requirement.
  2. B. Validate dataset provenance, remove or protect sensitive data, and restrict access to authorized training processes, within the proposed design.
  3. C. Disable data-quality checks because they can change model behavior, within the documented scope, ownership, and validation boundaries.
  4. D. Give all developers full dataset access for convenience, within the documented scope, ownership, and validation boundaries.

Correct answer

Validate dataset provenance, remove or protect sensitive data, and restrict access to authorized training processes, within the proposed design.

Where to go after the daily web set

How are CCSP questions generated?

dotCreds builds CCSP practice questions from public exam objectives and ISC2 exam and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start CCSP practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.